Postbank SOC has published a comprehensive Request for Bids/Proposals (RFB/P) for Information Security and Cybersecurity services, inviting qualified service providers to submit bids for a three-year engagement. The tender, designated 04/06/26-27, reflects the state-owned bank’s commitment to fortifying its critical banking infrastructure against escalating cyber threats, including ransomware, insider threats, data breaches, and service disruptions.
Tender Overview
The RFB/P seeks a strategic cybersecurity partner to deliver a full spectrum of managed security services over a three-year period. Bids must be submitted by 18 September 2026 at 11:00 AM, and proposals must remain valid for 180 days from the closing date. A non-compulsory briefing session will be held via Microsoft Teams on 31 August 2026 at 11:00 AM. The tender, published on 21 August 2026, falls under the Request for Bid (Open-Tender) type and is based in Gauteng, with services required at Postbank’s Pretoria offices.
Scope of Work
The appointed service provider will deliver comprehensive cybersecurity services across multiple domains:
- Security Operations Centre (SOC): 24/7 monitoring, detection, investigation, and response services
- Endpoint Security & XDR: Deployment and management of next-generation endpoint protection
- Zero Trust & Network Security: Implementation of network segmentation and micro-segmentation controls
- Identity & Access Management: Centralized Identity Governance and Administration (IGA) with MFA enforcement
- Privileged Access Management (PAM): Protection of all administrative, service, and privileged accounts
- Data Protection & Compliance: DLP controls, encryption, and HSM services aligned with PCI DSS and POPIA
- Incident Response & Forensics: Digital forensic investigation services and root cause analysis
- Threat Intelligence & Hunting: Proactive threat hunting and intelligence integration
- Patch & Vulnerability Management: Continuous vulnerability assessments and remediation within SLA timelines
- Cloud & Application Security: CSPM, SAST, DAST, and API security testing
Mandatory Documents Required
Bidders must submit the following mandatory documentation with their proposals:
- Signed Confirmation Letter: On official company letterhead confirming compliance with all specifications and capacity to deliver
- Team Credentials: Detailed CVs and valid copies of certifications for a minimum of two resources (one CISO-certified and one CISSP-certified)
- Local Presence Proof: Physical office address in South Africa (preferably Pretoria or Johannesburg) with supporting documents such as municipal account, lease agreement, or title deed
- Technical Response Document: Comprehensive proposal covering methodology, SOC architecture, cyber defense strategy, and transition plans
- Cyber Defence & Ransomware Strategy: Postbank-specific strategy addressing prevention, detection, containment, eradication, recovery, and reporting
- Banking Sector Experience: Evidence of delivering cybersecurity managed services to a regulated financial institution within the last three years
- Recovery Assurance Capability: Evidence of immutable backup solutions, recovery validation, and exercise participation
- Tax Compliance: SARS PIN or Central Supplier Database (CSD) number
Evaluation Criteria
The bid will be evaluated through a phased approach:
Phase 1: Mandatory Requirements – Bidders must comply with all mandatory criteria to proceed.
Phase 2: Functionality Requirements – Bidders are assessed on capability, requiring a minimum score of 70 points out of 100 on functionality to proceed. The evaluation covers company experience (25 points), track record (25 points), project resources (25 points), and regulatory compliance and certifications (25 points).
Phase 3: Live Demonstration – Bidders must demonstrate operational capabilities including SOC visibility, SIEM functionality, threat detection, incident response lifecycle, EDR/XDR capability, and ransomware attack scenarios.
Phase 4: Commercial Evaluation – Price (90 points) and Specific Goals (10 points) are evaluated under the 90/10 preference point system.
Related opportunity: Thulamela Municipality IT Equipment Tender Opens for Bids
Submission and Enquiries
- Submission Email: RFP@PostBank.co.za
- Closing Date: 18 September 2026 at 11:00 AM
- Enquiries Contact: Wilfred Vusi Maditsi
- Email: Vusi.Maditsi@Postbank.co.za
- Telephone: 076-706-9269
- Briefing Session: 31 August 2026 at 11:00 AM (Microsoft Teams, non-compulsory)
Tender Documents
Download the full tender document here.
Stay Updated
Want to stay informed about more tenders, funding opportunities, and business tips? Follow our updates on the StepApp Network:
- WhatsApp Channel: Follow StepApp Updates
- Facebook Page: Follow us
- WhatsApp Group: Join here
- LinkedIn Profile: Connect with StepApp
- X (Twitter): Follow StepApp SA on X
